GDPR · 2026-03-10 · 6 min

GDPR compliance checklist for US companies processing EU personal data

A structured checklist for US-based GRC teams establishing GDPR compliance when collecting, processing, or storing personal data of individuals in the European Economic Area.

By AuditOak GRC Team·907 words·6 min read

When GDPR applies to US organizations

The General Data Protection Regulation (GDPR) applies to US companies that process personal data of individuals in the European Economic Area (EEA), regardless of where the company is headquartered. Territorial scope under Article 3 covers organizations offering goods or services to EEA data subjects or monitoring their behavior.

Common triggers for US companies include: marketing to EU customers, providing SaaS platforms used by EU businesses, employing EU residents, processing EU customer support data, and using analytics or advertising technologies that track EEA visitors. Physical presence in the EU is not required.

GDPR enforcement against US companies is active. Supervisory authorities in the EU and UK have issued fines against US technology firms, and data protection authorities coordinate through the European Data Protection Board. US GRC teams should treat GDPR as a binding obligation, not a European-only concern.

Step 1: Data mapping and Records of Processing Activities

Article 30 requires organizations with 250 or more employees, or those processing high-risk data, to maintain Records of Processing Activities (RoPA). Even smaller US companies benefit from RoPA as the foundation for all other GDPR compliance activities.

Document each processing activity: what personal data is collected, purposes of processing, legal bases, data categories, recipient categories, retention periods, and cross-border transfer mechanisms. Include data processed by subprocessors and third-party integrations.

GRC teams should conduct a data inventory across product, marketing, HR, finance, and customer support functions. Personal data often exists in systems GRC teams do not initially consider: analytics platforms, email marketing tools, applicant tracking systems, and customer success platforms.

  • Inventory all systems processing EEA personal data
  • Document processing purposes and legal bases for each activity
  • Identify subprocessors and cross-border data flows
  • Define retention periods and deletion procedures

Step 3: Data subject rights procedures

GDPR grants data subjects eight rights: access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. US companies must establish procedures to receive, verify, and respond to requests within one month.

Build a Data Subject Access Request (DSAR) intake process with identity verification, request logging, and cross-functional workflow. Engineering, customer support, and legal should understand their roles in fulfilling requests within the statutory timeline.

Document response templates for common request types and maintain an audit trail of all DSAR handling. Supervisory authorities may request evidence of your DSAR process during investigations.

Step 4: Cross-border transfer mechanisms

Transferring EEA personal data to the US requires a valid transfer mechanism under Chapter V. Following the Schrems II decision and the EU-US Data Privacy Framework, US companies have several options: adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or explicit consent for specific transfers.

US companies certified under the EU-US Data Privacy Framework (DPF) benefit from an adequacy determination for transfers to certified entities. Organizations not DPF-certified should implement SCCs with supplementary measures where needed, following EDPB guidance on transfer impact assessments.

Maintain a transfer register documenting each cross-border flow, the mechanism used, and the assessment supporting that mechanism. Update transfer mechanisms when subprocessors change or when adequacy decisions are invalidated.

Step 5: Vendor management and Data Processing Agreements

Article 28 requires written Data Processing Agreements (DPAs) with every processor handling personal data on your behalf. DPAs must specify processing instructions, confidentiality obligations, subprocessor authorization, audit rights, and breach notification requirements.

US companies typically rely on dozens of subprocessors: cloud infrastructure, email services, analytics, payment processors, and customer support tools. GRC teams should maintain a subprocessor register and ensure DPAs are executed before processing begins.

Review subprocessor security practices as part of vendor due diligence. GDPR Article 28(1) requires that processors provide sufficient guarantees of appropriate technical and organizational measures.

Step 6: Security measures and breach notification

Article 32 requires appropriate technical and organizational measures based on processing risk. For most US SaaS companies, this includes encryption at rest and in transit, access controls, logging, vulnerability management, and incident response procedures.

Article 33 mandates breach notification to the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk to data subjects. Article 34 requires notification to affected data subjects when the breach poses high risk.

Establish a breach response plan that includes GDPR-specific notification timelines alongside your general incident response process. Pre-identify your lead supervisory authority if you have an EU establishment, or document your main establishment determination for organizations without EU presence.

Key takeaways

  • GDPR applies to US companies processing EEA personal data regardless of physical EU presence, based on Article 3 territorial scope.
  • Records of Processing Activities (RoPA) are the foundation for all GDPR compliance work; start with comprehensive data mapping.
  • Cross-border transfers to the US require valid mechanisms: DPF certification, SCCs with transfer impact assessments, or alternative safeguards.
  • Data Processing Agreements with all subprocessors are mandatory under Article 28 before processing begins.
  • Breach notification to supervisory authorities is required within 72 hours; prepare response procedures before an incident occurs.

Related compliance guides

Apply this guidance in your compliance program

Get a personalized, actionable checklist mapped to your frameworks and industry.

Start free, no credit card →

See your readiness in 5 minutes

Answer a few questions and get a personalized, actionable checklist, free, no card.

Get your free checklist →